Glossary
Cprotocols
Content-MD5
An HTTP header carrying an MD5 of the body so the server can reject a corrupt upload.
How it works
RFC 1864 defines it. It covers one message body, not a multipart object assembled later. MD5 is weak against attackers and fine against line noise. A SHA-256 beside the file is the stronger publishable check.
A client sends Content-MD5 on a 50 MB PUT. The proxy flips a bit. The store returns 400. The client retries. Without the header the bad object would have been stored.
How it differs
Content-MD5 is not a multipart ETag. One is a body hash. The other is often a hash of part hashes.
Attackers can recompute MD5. Do not use it as a signature.
Pair it with TLS.
On the ticket
- The practical close is a log line: time, actor, byte count, result.
- Without that line the transfer is a story.
- With it, the next person can see whether this door did what the ticket claimed.
- If the path is shared, say so in the partner profile so a later change does not silently pick a different limit, key, or region.
- On a real ticket, write down the door, the byte count, and the clock.
- For content md5, that means naming the host or bucket, the expected size, and the time the other side must have a complete file.
- A progress bar is not that record.
- A 200 response that arrives before the complete call is not that record.
- If a retry is allowed, say how many and whether it resumes.
- If a person must approve the send, name the person.
- Partners who receive content md5 files should match on hash or size before they import.
- A same-length corrupt file passes a size check and fails a hash.
- Keep the published hash off the only channel an attacker can edit, or treat it as a corruption check rather than a substitution check.
- When the path changes, new key, new region, new cap, update the profile the same day so the next run does not use a stale limit.
Related
Sources
- RFC 1864, Content-MD5
Integrity check for a message body